# Grokparsefailure when %{TIMESTAMP\_ISO8601} pattern is in the first position parser

**URL:** <https://discuss.elastic.co/t/grokparsefailure-when-timestamp-iso8601-pattern-is-in-the-first-position-parser/278308>\
**Category:** Logstash\
**Created:** [July 9, 2021, 9:15pm UTC](https://discuss.elastic.co/t/grokparsefailure-when-timestamp-iso8601-pattern-is-in-the-first-position-parser/278308 "2021-07-09T21:15:59Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Adixon\_Diaz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adixon_diaz/32/91182_2.png) [@Adixon\_Diaz](https://discuss.elastic.co/u/Adixon_Diaz)\
**Post date:** [July 9, 2021, 9:15pm UTC](https://discuss.elastic.co/t/grokparsefailure-when-timestamp-iso8601-pattern-is-in-the-first-position-parser/278308/1 "2021-07-09T21:15:59Z")

</div>

Hi Elastic Team,

I have a issue when in my grok filter y put first the pattern %{TIMESTAMP\_ISO8601}. I share a example:

With %{TIMESTAMP\_ISO8601} at first position:

![imagen](https://us1.discourse-cdn.com/elastic/original/3X/7/0/702670e31df116ceb565d690d6af3e15f740fe8d.png)

grok Debugger:

 ![imagen](https://us1.discourse-cdn.com/elastic/original/3X/4/0/40d852fe71839f5b37a66a8dbf9d20b6d77dc30e.png)

I got [1] "\_grokparsefailure"

 ![imagen](https://us1.discourse-cdn.com/elastic/original/3X/1/8/18a9d352f6e81aa1ec0528be70991a2cded8ace8.png)

With %{TIMESTAMP\_ISO8601} at second position:

![imagen](https://us1.discourse-cdn.com/elastic/original/3X/4/3/430e00be78cd30a85ef7dc9e92ccc1bd2a95d1a0.png)

grok Debugger:

 ![imagen](https://us1.discourse-cdn.com/elastic/original/3X/6/8/681c034a106abbb7a8ee61692ff83314f20564f4.png)

I got my parser without any problem:

 ![imagen](https://us1.discourse-cdn.com/elastic/original/3X/e/4/e4f4b233f9652547a6faa750d50dc1832a718a92.png)

I apreciate your feedback, thanks.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 9, 2021, 9:25pm UTC](https://discuss.elastic.co/t/grokparsefailure-when-timestamp-iso8601-pattern-is-in-the-first-position-parser/278308/2 "2021-07-09T21:25:08Z")

</div>

You need to show us the value of [message] that you are matching against.

Please do not post images of text, just post the text itself.

---

<div class="post-metadata">

**Author:** ![Adixon\_Diaz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adixon_diaz/32/91182_2.png) [@Adixon\_Diaz](https://discuss.elastic.co/u/Adixon_Diaz)\
**Post date:** [July 9, 2021, 9:28pm UTC](https://discuss.elastic.co/t/grokparsefailure-when-timestamp-iso8601-pattern-is-in-the-first-position-parser/278308/3 "2021-07-09T21:28:35Z")

</div>

Hi Badger,

Messsage with TIMESTAMP\_ISO8601 first: 2021-07-09 15:23:30.000 Adixon  
or  
Messsage with TIMESTAMP\_ISO8601 second: Adixon 2021-07-09 15:23:30.000

Thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 9, 2021, 9:47pm UTC](https://discuss.elastic.co/t/grokparsefailure-when-timestamp-iso8601-pattern-is-in-the-first-position-parser/278308/4 "2021-07-09T21:47:43Z")

</div>

```
input { generator { count => 1 lines => ['2021-07-09 15:23:30.000 Adixon'] } }
filter {
    grok { match => { "message" => "%{TIMESTAMP_ISO8601:date} %{WORD:test}" } }
}

```

produces

```
      "date" => "2021-07-09 15:23:30.000",
      "test" => "Adixon",

```

so I suspect [message] does not contain what you think it does.

---

<div class="post-metadata">

**Author:** ![Adixon\_Diaz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adixon_diaz/32/91182_2.png) [@Adixon\_Diaz](https://discuss.elastic.co/u/Adixon_Diaz)\
**Post date:** [July 9, 2021, 9:57pm UTC](https://discuss.elastic.co/t/grokparsefailure-when-timestamp-iso8601-pattern-is-in-the-first-position-parser/278308/5 "2021-07-09T21:57:34Z")

</div>

You're totally right Badger, my problem is the source, i use NXLOG for bring date to logstash, and when i search the timestamp i see:

```auto
 "Message" => "9044436 Adixon"

```

I mean the timestamp i recived but in number "9044436".

I think that i should see what happen in NXLOG.

---

<div class="post-metadata">

**Author:** ![Adixon\_Diaz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adixon_diaz/32/91182_2.png) [@Adixon\_Diaz](https://discuss.elastic.co/u/Adixon_Diaz)\
**Post date:** [July 13, 2021, 3:38pm UTC](https://discuss.elastic.co/t/grokparsefailure-when-timestamp-iso8601-pattern-is-in-the-first-position-parser/278308/6 "2021-07-13T15:38:25Z")

</div>

Hi team,

As solution, how Badger said, the key was see the message field. I see that the first caracter of the message always came different, example:

The field that i was looking: [7/12/21 15:40:58:862 CLT]  
The field that i recieved: 7/12/21 15:40:58:862 CLT]

or

The field that i was looking: 2021-07-09 18:47:30.000 ERROR Adixon  
The field that i recieved: 02021-07-09 18:47:30.000 ERROR Adixon

In both cases the first caracter changed and next i just was more carefully seeing first how message came and adapting my grok filter.

Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 10, 2021, 3:39pm UTC](https://discuss.elastic.co/t/grokparsefailure-when-timestamp-iso8601-pattern-is-in-the-first-position-parser/278308/7 "2021-08-10T15:39:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
